Summary
Some spam messages cannot be blocked by IMSS because the mail subject and message body are constantly changing. The spam mails also contain spoofed header information, such as data from address with the domain portion also changing to random spoofed domains.
Here is an example of an email that needs to be blocked by the IP address:
Microsoft Mail Internet Headers Version 2.0
Received: from sdmxmc-01t.NOC.local ([xxx.xx.x.xxx]) by sdnoce2k3.NOC.local with Microsoft SMTPSVC(6.0.3790.1830);
Thu, 21 Aug 2008 14:18:38 -0400 Message-ID:<2ee8e3640002fe43@noc.local>
Received: from web54502.mail.re2.yahoo.com (web54502.mail.re2.yahoo.com [xxx.xxx.xx.xxx])
Received: from sdmxmc-01t.NOC.local ([xxx.xx.x.xxx]) by sdnoce2k3.NOC.local with Microsoft SMTPSVC(6.0.3790.1830);
Thu, 21 Aug 2008 14:18:38 -0400 Message-ID:<2ee8e3640002fe43@noc.local>
Received: from web54502.mail.re2.yahoo.com (web54502.mail.re2.yahoo.com [xxx.xxx.xx.xxx])
The IP address to be blocked in this example is [xxx.xxx.xx.xxx].
Details
To resolve this issue, use the body keyword expressions by creating a new rule in the IMSS web console.
- Log on to the IMSS web console.
- Go to Policy > Policy List .
- Click the Add button.
- In Step 1, specify the Sender and Recipients and click Next.
- In Step 2, select Any match (or) in the Take rule action when drop-down list.
- Under Content, enable Body keyword expressions.
- Click Add, and then add the keyword expression.
- Click Save.
If the above steps did not resolve the issue, collect the files and logs using the Case Diagnostic Tool (CDT). Submit the collected files to Trend Micro Technical Support for further analysis.